diff --git a/app/fax/fax_edit.php b/app/fax/fax_edit.php
index 7de8123c5a..75b06f202e 100644
--- a/app/fax/fax_edit.php
+++ b/app/fax/fax_edit.php
@@ -397,7 +397,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
$fax_uuid = check_str($_GET["id"]);
$sql = "select * from v_fax ";
$sql .= "where domain_uuid = '".$_SESSION['domain_uuid']."' ";
- $sql .= "and fax_uuid = '$fax_uuid' ";
+ $sql .= "and fax_uuid = '".$fax_uuid."' ";
$prep_statement = $db->prepare(check_sql($sql));
$prep_statement->execute();
$result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
@@ -485,7 +485,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-email']."\n";
echo "\n";
echo "
\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo " ".$text['description-email']."\n";
echo " | \n";
@@ -499,7 +499,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-name']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo "".$text['description-name']."\n";
echo " | \n";
@@ -510,7 +510,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-extension']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo "".$text['description-extension']."\n";
echo " | \n";
@@ -522,7 +522,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo "\n";
echo "\n";
if ($action == "add") { $fax_accountcode = $_SESSION['domain_name']; }
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-accountcode']."\n";
echo " | \n";
@@ -533,7 +533,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-destination-number']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo " ".$text['description-destination-number']."\n";
echo " | \n";
@@ -544,7 +544,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-fax_prefix']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo " ".$text['description-fax_prefix']."\n";
echo " | \n";
@@ -561,7 +561,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
foreach($fax_emails as $email) {
echo "\n";
echo "| \n";
- echo " \n";
+ echo " \n";
echo " | \n";
$x++;
}
@@ -584,7 +584,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-caller-id-name']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo "".$text['description-caller-id-name']."\n";
echo " | \n";
@@ -595,7 +595,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-caller-id-number']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo "".$text['description-caller-id-number']."\n";
echo " | \n";
@@ -606,7 +606,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " ".$text['label-forward']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo "".$text['description-forward-number']."\n";
echo " | \n";
@@ -630,9 +630,9 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " \n";
foreach($result as $field) {
echo " \n";
- echo " | ".$field['username']." | \n";
+ echo " ".escape($field['username'])." | \n";
echo " \n";
- echo " $v_link_label_delete\n";
+ echo " $v_link_label_delete\n";
echo " | \n";
echo "
\n";
$assigned_user_uuids[] = $field['user_uuid'];
@@ -652,7 +652,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo " \n";
$result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
foreach($result as $field) {
- echo " \n";
+ echo " \n";
}
echo " ";
echo " \n";
@@ -712,7 +712,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
if ($file != "." && $file != ".." && $file[0] != '.') {
if (!is_dir($_SESSION['switch']['recordings']['dir']."/".$_SESSION['domain_name']."/".$file)) {
$selected = ($fax_send_greeting == $_SESSION['switch']['recordings']['dir']."/".$_SESSION['domain_name']."/".$file && strlen($fax_send_greeting) > 0) ? true : false;
- echo " \n";
+ echo " \n";
if ($selected) { $tmp_selected = true; }
}
}
@@ -729,7 +729,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) {
echo "